Take one small bug. At a payments start-up in Bengaluru, the app shows the old balance for a few seconds after a payment. A developer is asked to fix it. Before the fix reaches customers, it passes through the same few systems it would at any software company:
A ticket in the issue tracker says what to fix and who is fixing it.
The code change goes into the repository, where the code is kept and reviewed.
A pipeline builds the change and tests it.
The built version is stored in a registry.
The pipeline then pushes it to production, the live system that customers use.
The balance fix moves from a ticket to the repository, through the pipeline, which builds and tests it while security scanners check it, into the registry and out to production, and GitLab sells the whole path in one product.
Along the way, the app also talks to other software through APIs, for example to ask the bank to move the money.
This Market Segment is about the industry that sells these systems. Here the customer is the engineer, not the business.
Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out. Most of the companies here are well-known names, and most have engineers in Bengaluru. One large one, Postman, was founded in India. GitHub, the largest name in this field, is owned by Microsoft. It is covered elsewhere. (More on it in Microsoft, in the big-tech collection.)
This Market Segment has five sub-segments. The first follows the code from the ticket to production. The second covers tools that look at a whole application from above. The third covers APIs, and the ready-made building blocks that developers put together instead of writing everything themselves. The fourth moves to a different kind of engineer: one who designs the control system of a car or an aircraft as a model, before any code exists. The fifth covers the security scanners that plug into the same pipeline.
Where the code lives and how it ships
Issue trackers, code repositories, continuous integration and delivery (CI/CD), and artifact registries
Back to the balance bug from the start of this Market Segment. It begins as a ticket, and the code for the fix goes into a repository.
Atlassianmakes Jira, the issue tracker most software teams plan their work in. It also makes Bitbucket, the code repository that sits beside Jira. Its engineers are in Bengaluru and Kolkata. Atlassian sells a way for engineering teams to coordinate their work, as much as it sells tools.
GitLabwith engineers in Bengaluru and Delhi, sells the whole path in one product: the repository, the pipeline, the registry, and security scanning built into each step.
Next comes the pipeline. The industry calls it CI/CD. Continuous integration (CI) means every change is built and tested automatically as soon as it is added. Continuous delivery (CD) then pushes the tested change safely to production. (More on the tests in Market Segment 6.2, Software testing platforms.)
Harnesswas started in San Francisco by the founder of AppDynamics. It began with continuous delivery. It has since grown into a platform for the whole path from the code to the cloud, including what the company spends on the cloud. Its engineers are in Bengaluru.
CloudBeeswith a team in Chennai, sells the commercial version of Jenkins. Jenkins is the free, open-source automation server that older pipelines still run on.
When the pipeline builds the fix, the result is an artifact: a built package or a container image. A container image packs the app together with everything it needs to run. (More on containers in Market Segment 5.2, Enterprise Linux and private cloud platforms, in Industry Vertical 5, Cloud providers and OS makers.)
JFrogin Bengaluru, keeps these artifacts in its registry, called Artifactory. A registry like this is also called an artifact repository. JFrog scans them for known flaws on the way through. That scanning is why JFrog also appears in Market Segment 4.7, Application and API security (in Industry Vertical 4, Cybersecurity).
A few older or narrower companies complete this sub-segment:
Perforce Softwarewith engineers in Pune, sells version control, the job Git does, for very large files. Games studios and chip designers use it. Perforce also sells Klocwork and Helix QAC. These are static analysers: tools that read code without running it and flag mistakes. They check code against the safety standards for cars and aircraft. These analysers are part of the toolchain rather than security tools. That is why Perforce is covered here, and not in Market Segment 4.7, Application and API security (in Industry Vertical 4, Cybersecurity).
Appfirea Boston-area company with engineers in Hyderabad, builds the apps that extend Atlassian's products.
AutoRABITa San Francisco company whose engineers are in Hyderabad, serves one platform only: Salesforce. (More on Salesforce in Market Segment 14.1, CRM software, in Industry Vertical 14, CRM and sales tech.) Companies write their own code inside Salesforce to fit it to their business, so that code needs a toolchain too. AutoRABIT sells the pipeline, the code scanning and the backup for it.
One company here is an instruments maker instead: MKS, formerly called MKS Instruments.
Looking at the code from above
Mapping large applications, and measuring engineering work
The tools so far handle one change at a time, like the balance fix. Two companies sell a view of the code that no single developer has.
CASTa Paris company with an office in Bengaluru, reads an entire application: every language, every layer, every database call. It then draws a map of how the parts fit together and where they are fragile. Large companies use it before they move an old system to new technology or rebuild it, to know what they own. The industry calls such old systems legacy systems.
BlueOptimameasures the other side: the engineers. It analyses the changes committed to a repository and produces a measure of how much real work each change represents. Engineering leaders use it to compare their teams. They also use it to compare their vendors, the IT services firms they hire to write code for them. (More on these firms in the services-world collection.) Bengaluru is one of BlueOptima's engineering offices. Its idea, measuring engineers by their code, is contested: not everyone accepts it.
You're reading as a guest. Sign in free to follow links for five minutes, once an hour.
Sign in
The API and the building blocks
Tools to design, test and manage APIs, ready-made building blocks for developers, and low-code platforms
Back to the payments app from the start of this Market Segment. It does not do everything itself. It asks the bank to move the money, and a messaging service to send the receipt, all through APIs. Modern software is assembled this way, from services that talk to each other through APIs. This sub-segment covers the tools for designing, testing and managing those APIs, and the building blocks developers put together rather than write.
Postmanwas born in Bengaluru in 2014. Most developers have used it to try an API. It has grown into the workspace where APIs are designed, documented and tested. Its engineers are in Bengaluru and Hyderabad.
Kongwith engineers in Bengaluru, sells the gateway. A gateway sits in front of a company's APIs, and every request passes through it. It sends each request to the right service, checks that the caller is allowed in, and meters the traffic, meaning it counts every call. Kong's gateway is open source, and Kong has extended it to AI traffic.
Progresswith engineers in Bengaluru and Hyderabad, is a collection of developer building blocks under one roof. They include the Telerik and Kendo components for building user interfaces, the OpenEdge application platform, and the Chef configuration tool, which sets up servers automatically. Since 2024 it has also owned Citrix's ShareFile. Unlike the rest, ShareFile is a file-sharing service, not a developer tool.
SuprSenda young San Francisco company with its engineers in Bengaluru, sells one building block only: notifications. A developer sends a notification through one API, and SuprSend delivers it as an email, a push message or an alert inside the app. The payment receipt in our example could go out this way. SuprSend also appears in Market Segment 2.1, CPaaS and business messaging (in Industry Vertical 2, Business communications), for the same product.
Every request to the payments app's APIs passes through a gateway such as Kong's, which sends it to the right service, checks that the caller is allowed in and meters the call, and AI agents are now a new kind of caller.
Two companies here work differently. They sell low-code platforms, for building an application with as little code as possible. A developer assembles an internal application from ready-made components and connectors, rather than writing it. An internal application is one the company's own staff use, such as a screen for approving refunds.
ToolJetis an Indian open-source low-code platform, with teams in Bengaluru and Delhi.
OutSystemsis one of the large low-code vendors for big companies, with a team in Bengaluru.
Both are covered mainly in Market Segment 10.3, RPA, process mining and low-code platforms (in Industry Vertical 10, ERP and business automation).
Three other well-known API names are covered elsewhere, or not at all. Google's Apigee is covered elsewhere. (More on it in Google, in the big-tech collection.) MuleSoft, now part of Salesforce, is covered in Market Segment 10.2, Integration platforms (iPaaS) and managed file transfer (in Industry Vertical 10, ERP and business automation). (More on Salesforce in Market Segment 14.1, CRM software, in Industry Vertical 14, CRM and sales tech.) Swagger belongs to SmartBear. (More on SmartBear in Market Segment 6.2, Software testing platforms.) Other API gateway vendors are not covered in this Market Segment.
The API for the agent.
An AI agent is software that uses a language model, the kind of AI behind chatbots, to take actions on its own, for example by calling an API. The gateway and the API workspace are both being rebuilt for this new caller. Kong's gateway now routes and meters requests from language models, just as it does requests from applications. Postman has become the place where an API is described so that an agent can use it. The developer's building blocks are becoming the agent's.
Maths and models for engineers
Numerical computing, simulation, and designing control systems as models
Not every engineer starts with code. At a carmaker in Pune, an engineer designing the braking control for a new car first builds it as a model. One company in this Market Segment serves engineers like this, before a line of production code exists.
MathWorksmakes MATLAB, the numerical computing environment taught in many engineering degrees. It also makes Simulink. In Simulink, a control system for a car, an aircraft or a power grid is drawn as a model and simulated. Simulink then turns the model into the code that runs on the machine. The industry calls this model-based design. MathWorks has engineering teams in Bengaluru and Hyderabad.
In model-based design, an engineer draws the braking control as a model in Simulink, simulates it, and lets Simulink turn the model into the code that runs on the car's controller.
MathWorks also appears in Market Segment 37.2, CAD and PLM software (in Industry Vertical 37, Manufacturing tech), for the same product. The design and simulation suites of Dassault Systèmes and PTC are covered there too.
Wolfram and COMSOL are not covered in this Market Segment. Ansys is now part of Synopsys. (More on Synopsys in Market Segment 35.7, Chip design software (EDA), in Industry Vertical 35, Semiconductors and chip design.)
Security in the pipeline
Security scanners that run inside the pipeline
Back to the balance fix at the Bengaluru payments start-up. The scanners that check code for vulnerabilities are security products, but they run inside the toolchain this Market Segment describes. Before the pipeline pushes the fix to production, they check it. Three of them are here:
Black Duckwith engineers in Bengaluru, scans the open-source libraries a build pulls in. Through its Coverity analyser, it also scans the code the team wrote itself.
Checkmarxin Pune, scans the source code.
Revenerain Bengaluru, tracks the open-source licences and known vulnerabilities inside a product. A licence sets the rules for how a piece of open-source code may be used.
All three are covered mainly in Market Segment 4.7, Application and API security (in Industry Vertical 4, Cybersecurity). Each one is a step in the pipeline from the first sub-segment. Together with the scanning built into GitLab and JFrog, they are why the toolchain and security cannot be understood apart.
That is the developer's toolchain. A fix like the balance bug moves from the ticket to the repository, through the pipeline and its scanners, into the registry and out to customers. Around that path sit the tools that map and measure the code, and the APIs and building blocks the app is made from. For some engineers, the work starts even earlier, with a model built before any code exists.